Legal

Privacy Policy

This privacy notice describes how HunterTag collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR).

Last updated: 26.07.2026 (version 2026-07-26)

In short

HunterTag lets you register a bicycle, pair it with an NFC tag and recover it if it is stolen. Doing so requires processing some of your personal data. This notice explains which data, why, for how long, and what you can ask us.

The points worth knowing straight away: we record the location of tag scans, because that is what makes recovering a stolen bike possible; we keep the GPS coordinates embedded in sighting photographs, but the photographs shown to other users are stripped of that metadata; we do not sell data to anyone; you can download all your data and delete your account yourself from the account settings.

Data controller

The data controller is the company that decides why and how your data is processed. For HunterTag that is:

Company: HunterTag S.r.l.

Registered office: Via de Taddei 3, Milan, Italy

VAT number: 14244060969

Email: privacy@huntertag.com

Data protection officer

We have not appointed a Data Protection Officer, as we consider that the conditions set out in Article 37 of the Regulation are not met at our current processing volume. That assessment is reviewed as the service grows.

For any matter concerning personal data, the contact point is privacy@huntertag.com.

What data we process

We collect only the data needed for the purposes described below. Some of it you provide; some is generated by using the service.

Account and profile

  • Email address and password. The password is never stored in readable form: we keep only an irreversible version of it.
  • First name, last name, display name, language and time zone.
  • Optional: phone number, date of birth, address.
  • If you sign in with Google: your email address, name and Google account identifier. We do not receive your Google password.

Bicycles and tags

  • Make, model, frame number, year, colour, declared value.
  • Photographs you upload.
  • Status of the bike (active, stolen, recovered, scrapped) and ownership history.
  • Identifier of the paired NFC tag.

Tag scans

  • Date, time and geographic location of the scan, where your device provides it and you have allowed its use.
  • Tag identifier in irreversible form, and the outcome of the cryptographic check.
  • Device and browser type, IP address stored in irreversible form.
  • Anomaly indicators we compute ourselves, described below.
  • Scans are recorded even when the person scanning has no account: in that case they are linked to a temporary session identifier, not to a person.

Sighting reports

  • Photographs, location and notes from whoever reports seeing a bike.
  • The GPS coordinates and capture date contained in the photographs, where present.

Messages and support

  • The content of messages exchanged within the platform and of support requests.

Payments

  • Amount, status and transaction references.
  • IBAN, for refunds and for hunter rewards.
  • Payment card details never pass through our systems: they are handled directly by the payment provider.

Security and logs

  • Date, time and IP address of sign-ins, in irreversible form.
  • Failed sign-in attempts.
  • A record of operations performed by our staff on user data, including simple lookups.

Consent

  • A record of every consent granted or withdrawn, with the date, the version of the text in force at that moment, and where the choice came from.

Why we process this data, and on what basis

Every processing activity has a purpose and a legal basis. Where the basis is consent, you may withdraw it at any time without affecting what happened before.

Providing the service

Creating and managing your account, registering bikes, pairing tags, verifying scans, handling ownership transfers and support. Legal basis: performance of the contract (Art. 6(1)(b)).

Recovering stolen bikes

Alerting the owner when a tag paired with a reported bike is scanned, and showing where and when. Legal basis: performance of the contract towards the owner, and legitimate interest (Art. 6(1)(f)) in respect of the person scanning.

Preventing fraud and abuse

Detecting cloned tags, falsified coordinates and unauthorised access attempts. Legal basis: legitimate interest in the security of the service (Art. 6(1)(f)), expressly recognised by Recital 49.

Legal obligations

Accounting and tax obligations, responding to lawful requests from authorities, and demonstrating the consent we have collected. Legal basis: legal obligation (Art. 6(1)(c)).

Site measurement

Understanding how the site is used in order to improve it. Legal basis: your consent, which you can give or refuse from the banner and withdraw from the Cookie preferences link in the footer.

Promotional messages

Sending you news about the service. Off by default: you will only receive them if you turn them on. Legal basis: your consent.

Location, photographs and device characteristics

These are the three points we think deserve a fuller explanation, because they concern data that says a great deal about you.

Scan location. We record where a scan happens because that is precisely the information that makes recovering a stolen bike possible; without it the service would not work. Location is captured only if your device provides it and you have allowed its use in the browser.

Sighting photographs. When you upload a photograph of a bike you have seen, if the file contains GPS coordinates and a capture date we extract and keep them as separate data: they say where the bike actually was, which is the most useful piece of information in a recovery. The photograph other users see is, however, a version stripped of that metadata, because the same image also reveals where you were when you took it.

Device characteristics. Collecting the technical characteristics of your device for anti-fraud purposes is off unless you give explicit, separate consent, which you can grant and withdraw from your settings. We do not rely on legitimate interest here: Article 122 of the Italian Privacy Code requires consent to access information stored on your terminal, and the service works without it.

Anomaly indicators. We compare each scan with the previous one on the same tag and compute distance, elapsed time and the resulting speed. If the result is not physically possible, the event is flagged for review. This is not automated decision-making within the meaning of Article 22: the score produces no effect on you by itself, it directs a human assessment.

Who we share data with

We do not sell personal data and we do not pass it to third parties for marketing purposes. We use providers who process it on our behalf and on our instructions, acting as processors:

  • MongoDB Atlas: primary database, on European infrastructure.
  • Railway: running the application.
  • Cloudflare R2: encrypted backups.
  • Cloudinary: storage and delivery of photographs.
  • Resend: sending service emails.
  • Sentry: collecting error reports, on European infrastructure.
  • Stripe: payment handling.
  • Google: sign-in with a Google account, if you choose to use it.
  • Other users: if you report sighting a bike, the owner receives your report, the location and the photographs stripped of metadata. If you transfer a bike, the buyer receives the bike data and the ownership history.
  • Public authorities: only upon a request grounded in law, and limited to the data we actually hold.

Transfers outside the European Union

The primary database and the error reporting service run on European infrastructure. Some of the other providers listed above may process data outside the European Economic Area as well.

Where that happens, the transfer takes place on the basis of the standard contractual clauses adopted by the European Commission or of an adequacy decision. You can request a copy of the safeguards applied by writing to privacy@huntertag.com.

No personal data of European users is currently transferred to China. Should that change in the context of a commercial relationship, this notice will be updated before any such transfer takes place.

How long we keep data

Account and profile:for as long as the account exists
Inactive accounts:flagged for deletion after 3 years of inactivity
Bike data:for as long as the bike is linked to your account
Scans:24 months, except those concerning a bike reported stolen, which are kept while the report is open
Closed conversations:24 months
Record of staff operations:5 years
Application technical logs:about 30 days
Spent transfer codes:90 days
Accounting records:10 years, as required by Article 2220 of the Italian Civil Code
Ownership history:kept in anonymised form even after the account is deleted

Why ownership history survives deletion

This is the one significant exception to the right to erasure, and we would rather explain it than bury it in a single line.

When you delete your account, your personal data is removed. The sequence of ownership transfers remains recorded in anonymised form, with no reference to you. Without that sequence, whoever bought the bicycle after you could no longer show where it came from, and the very function of the service would be lost: telling a bike with a verifiable history apart from a stolen one.

We consider this retention to be covered by Article 17(3)(e) of the Regulation and by the legitimate interest of subsequent owners. If you believe it is not justified in your case, you may object by writing to us.

Your rights

You can exercise them at any time by writing to privacy@huntertag.com. We reply within one month. Some you can exercise yourself from your account settings, without waiting.

Access

Find out what data we process and obtain a copy of it (Art. 15).

Portability

Download your data in a machine-readable format. Available immediately from your account settings (Art. 20).

Rectification

Correct inaccurate data. Profile data can be edited from your settings (Art. 16).

Erasure

Delete your account and the data linked to it, available from your settings. Data we are legally required to keep and the anonymised ownership history remain, for the reasons explained above. We send you a confirmation email before removing your address (Art. 17).

Restriction

Ask that processing be suspended pending a verification (Art. 18).

Objection

Object to processing based on our legitimate interest, setting out your particular situation (Art. 21).

Withdrawal of consent

Withdraw a consent already given, as easily as you gave it: from your settings, from the Cookie preferences link, or from the unsubscribe link present in every non-essential email (Art. 7(3)).

Complaint

Lodge a complaint with the Italian Data Protection Authority, www.gpdp.it, if you believe the processing infringes the Regulation (Art. 77).

How we protect data

Without going into detail that would help anyone wishing to attack us:

  • Passwords are not stored: we keep only an irreversible version of them.
  • The most sensitive data, including IBAN, phone number, date of birth, street and postal code, is encrypted at rest.
  • IP addresses in logs are never stored in the clear: they are encrypted, and readable only with a key we keep separately. Anyone obtaining the logs without that key could not derive any address from them.
  • Access to data by our staff is tiered: support staff see a reduced version of the profile. Every lookup leaves a trace recording who looked, when, and which data they saw.
  • Two-factor authentication is available.
  • Backups are encrypted.
  • We have a written procedure for handling personal data breaches, providing for notification to the supervisory authority within 72 hours where the breach poses a risk to your rights, and direct communication to affected individuals where the risk is high.

Cookies and similar technologies

We use the technical cookies needed to keep you signed in and to make the site work: these require no consent, because without them the service cannot be provided.

Measurement tools and any other non-essential technology are enabled only if you allow them from the banner shown on your first visit. Your choice is recorded together with the date and the version of the text you read.

You can change your mind at any time from the Cookie preferences link in the footer, which reopens the same choice.

Minors

The service is not directed at people under 16 and is not designed for them. We do not verify age at registration: we would rather say so than claim a check we do not perform. If we become aware that an account belongs to someone under 16 without the consent of the holder of parental responsibility, we delete it. If you believe a minor has provided us with data, write to privacy@huntertag.com.

Changes to this notice

If this notice changes substantially we will tell you by email or through a notice in the platform, and we will ask you to review it on your next sign-in. We record which version you saw and when, so that it is always possible to establish which text was in force at a given moment. The current version and the date of last update are shown at the top of this page.

Contact

Email: privacy@huntertag.com

Address: HunterTag S.r.l., Via de Taddei 3, Milan, Italy

Supervisory authority: Garante per la protezione dei dati personali, www.gpdp.it

For requests under Articles 15 to 22 of the Regulation we reply within one month, extendable by two further months for particularly complex requests, of which we will inform you.